CPA: The Complete Guide
The Colorado Privacy Act, signed into law in July 2021 and effective July 1, 2023, is one of the most consumer-friendly state privacy laws in the United States. It stands out for its requirement that businesses recognize universal opt-out mechanisms, making it easier for consumers to exercise their privacy preferences across multiple organizations simultaneously. Colorado followed Virginia's framework closely but added several consumer-protective enhancements that have since influenced other state privacy laws.
What the CPA Is and Who Enforces It
The CPA was signed into law by Governor Jared Polis on July 7, 2021. The Colorado Attorney General and district attorneys share enforcement authority. There is no private right of action — only governmental enforcement is available.
An important procedural distinction from Virginia: the CPA's initial 60-day cure period expired on January 1, 2025. From that date, the AG and district attorneys may pursue enforcement without offering a prior opportunity to cure. This makes Colorado one of the more enforcement-ready state privacy laws, as organizations cannot rely on a cure period to avoid consequences for identified violations.
The Colorado AG's office has indicated it will prioritize enforcement of the universal opt-out mechanism requirement and data protection assessments for high-risk processing — the two areas most distinctively associated with the CPA relative to other state laws.
Territorial and Material Scope
The CPA applies to controllers that conduct business in Colorado or intentionally target Colorado residents and either:
- Control or process the personal data of 100,000 or more Colorado consumers during a calendar year, or
- Derive revenue or receive a discount on goods or services from the sale of personal data and control or process the data of 25,000 or more Colorado consumers annually.
Unlike the CCPA, the CPA's revenue threshold is specifically tied to revenue from the sale of personal data — general business revenue does not count. This narrows the revenue-based threshold substantially compared to California.
Significant exemptions apply:
- Personal data regulated by HIPAA, GLBA, FERPA, COPPA, and several other federal frameworks.
- Nonprofit organizations — exempt in full.
- Institutions of higher education — exempt.
- Air carriers, consumer reporting agencies, and financial institutions regulated under federal law.
The nonprofit exemption distinguishes the CPA from several other state laws that include nonprofits within scope.
Consumer Rights
The CPA grants Colorado consumers five core rights analogous to the VCDPA:
- Right to access — Confirm processing and access personal data held by the controller.
- Right to correct — Correct inaccuracies in personal data.
- Right to delete — Delete personal data, including data provided by or obtained about the consumer.
- Right to data portability — Obtain a portable, readily usable copy of personal data where technically feasible.
- Right to opt out — Opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects.
Controllers must respond to consumer requests within 45 days, with a 45-day extension available with notice. Denied requests must be accompanied by a reason and an appeal mechanism. Controllers must respond to appeals within 45 days and notify consumers of their right to file a complaint with the AG.
Universal Opt-Out Mechanism — Colorado's Distinctive Requirement
The CPA's most distinctive feature is its universal opt-out mechanism (UOOM) requirement, which took effect January 1, 2024. Controllers must recognize technology-enabled opt-out signals — such as the Global Privacy Control (GPC) — that communicate a consumer's preference to opt out of the sale of personal data, targeted advertising, and profiling.
This means organizations cannot require consumers to submit individual opt-out requests to exercise their rights. If a consumer's browser or device sends a GPC signal, the controller must treat it as a valid opt-out request and honor it. The AG's office has specifically flagged this as a technical requirement that cannot be met with privacy policy language alone — it requires backend technical implementation.
The CTDPA adopted a similar UOOM requirement effective January 1, 2025. The CPRA also requires GPC recognition in California. Organizations serving consumers across these states should implement GPC recognition as a single technical project covering all three jurisdictions.
Sensitive Data
Sensitive data under the CPA includes: racial or ethnic origin, religious beliefs, mental or physical health conditions or diagnoses, sexual orientation, citizenship or immigration status, financial data beyond publicly available information, genetic or biometric data used for unique identification, personal data from children known to be under 13, and precise geolocation data.
Processing sensitive data requires opt-in consent before collection. This is a stricter standard than the CCPA's notice-and-opt-out approach and mirrors the consent model for special categories under the GDPR.
Data Protection Assessments
Controllers must conduct and document data protection assessments for high-risk processing activities:
- Selling personal data.
- Processing for targeted advertising.
- Processing for profiling that presents a foreseeable risk of injury, intrusion upon solitude, financial harm, or other substantial harm.
- Processing sensitive data.
- Any other processing that presents a heightened risk as defined by rule.
Assessments must weigh benefits against risks, considering available safeguards. The AG may require access to data protection assessments during investigations. Assessments are not required for processing occurring before July 1, 2023, but controllers should document ongoing assessments for all high-risk activities commenced after that date.
Colorado's Rulemaking Under the CPA
Colorado's Attorney General promulgated detailed rules implementing the CPA that took effect in 2023 and were updated in 2024. The rules address:
- Technical specifications for recognizing universal opt-out signals.
- Requirements for authentication of consumer rights requests without requiring more information than necessary.
- Guidance on data protection assessment documentation.
- Requirements for data processing agreements.
- Dark patterns — consent or opt-out mechanisms designed to subvert consumer choice are prohibited.
Colorado's rulemaking is more detailed than most other state privacy laws, providing both clearer compliance guidance and higher expectations for technical implementation.
CPA vs. GDPR and Related Laws
The CPA shares approximately 60% structural overlap with the GDPR and approximately 80% with the VCDPA. Key similarities with the GDPR: opt-in for sensitive data, data protection assessments analogous to DPIAs, controller-processor framework. Key differences: CPA operates on opt-out default for most processing; GDPR requires lawful basis before processing begins.
Compared to the CCPA, the CPA has lower revenue thresholds (sale-of-data revenue only) and adds the universal opt-out requirement and data protection assessments. Compared to the CTDPA (85% overlap with CPA), the two laws are nearly identical in structure with minor differences in consent thresholds and loyalty program transparency provisions.
For organizations building a unified US multi-state privacy program, the Virginia-Colorado-Connecticut template is the practical framework. Meeting all three with a unified program requires: implementing the VCDPA base obligations, adding GPC/UOOM recognition for Colorado and Connecticut, and confirming loyalty program transparency for Connecticut.
Compliance Steps and Timeline
| Phase | Activities | Typical Duration |
|---|---|---|
| Assessment | Applicability analysis, Colorado-specific threshold check, data inventory | 2-3 weeks |
| Design | GPC/UOOM implementation, sensitive data consent, privacy notice update | 3-5 weeks |
| Implementation | Consumer rights workflows, DPAs with processors, assessments documentation | 3-6 weeks |
| Ongoing | Assessments for new activities, UOOM monitoring, AG guidance tracking | Continuous |
Key compliance steps:
- Universal opt-out — Implement technical recognition of GPC and other CPA-compliant universal opt-out signals.
- Consent management — Deploy opt-in mechanisms for sensitive data categories before any collection begins.
- Consumer rights workflows — Build intake, verification, and response processes meeting 45-day deadlines with appeal procedures.
- Data protection assessments — Document assessments for all targeted advertising, sale, profiling, and sensitive data processing activities.
- Privacy notice updates — Disclose categories of data, purposes, rights, opt-out methods, and identify whether sale or targeted advertising occurs.
- Dark patterns audit — Review all consent mechanisms and opt-out flows to ensure they do not subvert consumer choice in ways prohibited by CPA rules.
How Privacy Automation Helps
The CPA's universal opt-out requirement, 45-day response window, and data protection assessments benefit significantly from automated privacy operations. TruePrivacy covers the CPA alongside VCDPA, CCPA, CPRA, and CTDPA within its 12-plus framework portfolio. AI data discovery across 128-plus sources supports the data mapping needed to accurately disclose processing activities and complete data protection assessments. DSR automation handles the 45-day response requirement across multiple simultaneous state laws.
At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is a practical fit for organizations managing a growing portfolio of US state privacy laws. See best privacy management tools for broader comparisons.
Frequently Asked Questions
What is the Global Privacy Control and how do we implement it? The Global Privacy Control (GPC) is a technical specification that allows users to signal their privacy preferences through a browser or browser extension. When a user activates GPC, it sends a "Sec-GPC: 1" header with HTTP requests. Organizations subject to CPA's UOOM requirement must detect this signal server-side and treat it as a valid opt-out of sale, targeted advertising, and profiling for that user. Implementation requires backend development to detect the header and apply appropriate processing restrictions to the flagged user's data.
What counts as "sale of personal data" under the CPA? The CPA defines "sale" as the exchange of personal data for monetary consideration by the controller to a third party. Unlike the CPRA, the CPA does not extend "sale" to include non-monetary consideration or sharing for advertising purposes. Sharing personal data with third-party advertisers without direct monetary payment may not constitute a "sale" under the CPA — instead, it may fall under "targeted advertising" which triggers opt-out rights separately.
Does the CPA's 60-day cure period really have no sunset? Correct — the cure period expired on January 1, 2025, with no sunset extension. From that date, the AG and district attorneys can pursue enforcement without providing a 30-day or 60-day cure notice. This distinguishes Colorado from Virginia (where the 30-day cure period remains) and makes prompt remediation of identified violations more important.
Are data protection assessments confidential? The CPA provides that data protection assessments requested by the AG in connection with an investigation are confidential and not subject to public disclosure or inspection under Colorado open records laws. This protection does not apply to assessments in contexts outside AG investigations. Organizations should treat assessments as privileged internal compliance documents with restricted access.
How does Colorado's nonprofit exemption work? Nonprofit organizations are fully exempt from the CPA — both the controller obligations and the consumer rights framework. This is broader than some other state laws. A nonprofit association, charitable organization, or other nonprofit entity processing personal data of Colorado residents does not need to comply with the CPA, regardless of the volume of data processed. The nonprofit's for-profit subsidiaries or controlled entities, however, are not automatically exempt and must separately qualify for exemption.